Senior Vulnerability Management Analyst

  • Full-time
  • Clearance Required: Secret

Company Description

MindPoint Group delivers industry-leading cybersecurity solutions, services, and products. We are the trusted cybersecurity advisors to key government and commercial decision-makers and support security operations for some of the most security-conscious organizations globally. We design and implement innovative security solutions to identify and defend against today’s risks and tomorrow’s attacks.  

We believe that helping organizations operate from the best security posture possible requires automation.  Empowering our employees to excel and providing them with the means to do so enables us to consistently exceed our clients’ expectations. 

Unlike many IT consultancies, we’re not a body shop. Our client engagements are challenging and growth-oriented. Our relationship with you is for the long run because, in this business, your success is our success. That’s why we treat investments in employees as investments in the company itself, which is why we offer fantastic benefits (healthcare, generous PTO, paid maternity and paternity leave, and tuition reimbursement, to name a few). 

But you’ll want to work here for reasons that can’t be written into an offer letter—the challenge, growth opportunities, and most important: the culture of a company that cares about you. 

We are an established, profitable, and growing company that promises you the following: 

  • A diverse organization. 
  • A safe workplace with zero tolerance for discrimination and harassment of any kind. 
  • A balanced work life. Seriously. 
  • Potential of a flexible schedule, depending on the specific customer. 
  • A leadership team focused on your professional growth and development. 

Job Description

MindPoint Group is seeking a Senior Vulnerability Management Analyst to assist our Federal client in the development and maintenance of the full lifecycle of vulnerability management services from discovery, triage, advising, remediation, and validation. The role can be remote. The candidate will:

  • Support the development and maintenance of vulnerability management services, including vulnerability scanning, vulnerability assessments, and providing advisory and tracking support for vulnerability remediation.
  • Operate and configure agency tools used for vulnerability testing and identification
  • Review agency vulnerability management plans / policies and update documents as needed
  • Coordinate with customers regarding scanning schedule and scope
    Review, analyze, validate, and report on vulnerability scan results
  • Develop and disseminate operational and executive-level reports on vulnerability status to stakeholders involved in remediating vulnerabilities
  • Work with stakeholders as necessary to develop vulnerability remediation strategies and track status
  • Identify areas for improvement and/or efficiencies including processes, tools, and template; Identify relevant metrics
  • Develop processes and document procedures in an Standard Operating Procedures (SOP) format for use by other team members and to enhance efficiencies
  • Coordinate with other teams, including ISSOs and penetration testers to share information as needed
  • Opportunity to perform security testing activities, such as penetration testing and application / vulnerability assessment

Qualifications

  • Active Secret clearance required
  • Minimum of 5 years of professional experience in information security or information technology roles; 4 years of experience in Vulnerability Management preferred.
  • Bachelor’s Degree, or an equivalent combination of formal education, experience preferred
  • Experience conducting vulnerability scans, including configuration and use of tools such as Tenable Security Center and/or Qualys
  • Experience executing security testing activities such as penetration testing and application / vulnerability assessments preferred
  • Knowledge of cybersecurity frameworks, controls and standards, and best practices (e.g., FISMA, ISO 27K, CMMC, NIST)
  • Knowledge of cloud and network security
  • Proven track record of identifying and recommending improvement initiatives
  • Excellent people skills and the ability to work both independently and in a team environment
  • Excellent communication skills, both written and verbal 
  • Excellent organizational skills with the ability to multi-task and meet deadlines

Additional Information

  • All your information will be kept confidential according to EEO guidelines
  • Equal Opportunity Employer Veterans/Disabled